PT-2026-98147 · Libde265 · Libde265
CVE-2026-88373
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libde265 versions prior to commit 4d45a6b
Description
A NULL pointer dereference exists in the NAL parsing path. When the function
de265 push NAL() is called with a zero-length NAL unit, the resulting NAL unit may retain a NULL backing buffer. This buffer is then passed as the destination argument to memcpy() within the NAL unit::set data() function. Even though the copy length is zero, this violates the nonnull requirement of memcpy(), leading to undefined behavior, process termination in UBSan-instrumented builds, and denial of service.Recommendations
Update to a version of libde265 that includes the fix implemented after commit 4d45a6b.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libde265